aboutsummaryrefslogtreecommitdiffstats
path: root/libAACdec
diff options
context:
space:
mode:
authorFraunhofer IIS FDK <audio-fdk@iis.fraunhofer.de>2018-11-05 15:09:12 -0800
committerandroid-build-merger <android-build-merger@google.com>2018-11-05 15:09:12 -0800
commitac56cddd1f2809aab2acc3b268eb78a3c9467d65 (patch)
tree1e9b04e0f211d0000c457ca12f8d908571568508 /libAACdec
parentadd26c57dec427b36ad65841ace7c8ea7066ce90 (diff)
parenta4d6ca7b07569aac07d50f894f3757b58dd2d6eb (diff)
downloadfdk-aac-ac56cddd1f2809aab2acc3b268eb78a3c9467d65.tar.gz
fdk-aac-ac56cddd1f2809aab2acc3b268eb78a3c9467d65.tar.bz2
fdk-aac-ac56cddd1f2809aab2acc3b268eb78a3c9467d65.zip
Merge "Fix huffman decoder escape sequence length limitation."
am: a4d6ca7b07 Change-Id: I6cac7c525c4b5c5afca58ac6ab3d2c8925fc343e
Diffstat (limited to 'libAACdec')
-rw-r--r--libAACdec/src/block.cpp12
1 files changed, 7 insertions, 5 deletions
diff --git a/libAACdec/src/block.cpp b/libAACdec/src/block.cpp
index 7d2a4b9..b3d09a6 100644
--- a/libAACdec/src/block.cpp
+++ b/libAACdec/src/block.cpp
@@ -127,9 +127,11 @@ amm-info@iis.fraunhofer.de
The function reads the escape sequence from the bitstream,
if the absolute value of the quantized coefficient has the
value 16.
- A limitation is implemented to maximal 31 bits to prevent endless loops.
- If it strikes, MAX_QUANTIZED_VALUE + 1 is returned, independent of the sign of
- parameter q.
+ A limitation is implemented to maximal 21 bits according to
+ ISO/IEC 14496-3:2009(E) 4.6.3.3.
+ This limits the escape prefix to a maximum of eight 1's.
+ If more than eight 1's are read, MAX_QUANTIZED_VALUE + 1 is
+ returned, independent of the sign of parameter q.
\return quantized coefficient
*/
@@ -139,11 +141,11 @@ LONG CBlock_GetEscape(HANDLE_FDK_BITSTREAM bs, /*!< pointer to bitstream */
if (fAbs(q) != 16) return (q);
LONG i, off;
- for (i = 4; i < 32; i++) {
+ for (i = 4; i < 13; i++) {
if (FDKreadBit(bs) == 0) break;
}
- if (i == 32) return (MAX_QUANTIZED_VALUE + 1);
+ if (i == 13) return (MAX_QUANTIZED_VALUE + 1);
off = FDKreadBits(bs, i);
i = off + (1 << i);